PT-2026-104150 · WordPress · Jetformbuilder
CVE-2026-97342
·
Published
2026-10-02
·
Updated
2026-10-02
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress versions prior to 3.6.5.5
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting. An attacker can inject arbitrary web scripts via the
wp ajax nopriv jet form builder submit endpoint. The payload is stored in post meta through the Insert/Update Post action using the choice variable. These scripts execute when a user accesses a page where the Select Field block template renders the raw meta values into option value attributes and label content via the get from db option generator.Recommendations
Update the plugin to version 3.6.5.5 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jetformbuilder